
gh-workflow-auditor
Script to audit GitHub Action Workflow files for potential vulnerabilities.

Script to audit GitHub Action Workflow files for potential vulnerabilities.

查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293

LLM powered fuzzing via OSS-Fuzz.


AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

sprint encode (plan text) get enc password

Idempotent functions for IBM Security Appliance REST APIs. Currently covering ISAM and ISDS Appliances.

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

OWASP Security Culture repository

An open source threat modeling tool from OWASP

Burp Extension for collaboration in Faraday

OPNsense GUI, API and systems backend